UK Cyber Security and Resilience Bill Clears the Commons: What Changes Under the New NIS Rules

UK Cyber Security and Resilience Bill Clears the Commons: What Changes Under the New NIS Rules

The Bill was introduced to the House of Commons on 12 November 2025, had its second reading on 6 January 2026, and went through committee stage between February and March 2026. It was reintroduced on 14 May 2026 following a carry over motion, and reached report stage and third reading on 10 June 2026. The legislation extends to the whole of the UK and amends the existing NIS Regulations, which currently govern how operators of essential services and certain digital providers manage cyber risk and report incidents.

What the source data shows

The Bill expands the regulatory perimeter of the NIS Regulations to bring data centres, large load controllers, and managed service providers (MSPs), companies that remotely manage IT infrastructure for other organisations, into scope. It also introduces powers for regulators to designate specific organisations as critical suppliers for additional oversight, and creates a two tier penalty regime for non compliance.

AreaCurrent NIS Regulations 2018Cyber Security and Resilience Bill
Regulated entitiesOperators of essential services and relevant digital service providersAdds data centres, large load controllers, and managed service providers
Critical suppliersNo separate designation powerNew power to designate critical suppliers for added oversight
PenaltiesSingle penalty frameworkNew two tier penalty regime
Geographic scopeApplies across the UKContinues to apply across the whole of the UK
Incident reportingExisting thresholds did not capture incidents such as Synnovis or Marks & SpencerBill is intended to tighten incident reporting timelines and widen what must be reported

Table 1. Summary of how the Cyber Security and Resilience Bill changes the existing UK NIS Regulations 2018. Source: House of Commons Library briefing (CBP-10442) and DigitalXRAID, March 2026.

Why it matters

Two recent incidents have been cited repeatedly in support of the Bill because neither triggered mandatory reporting under the current NIS Regulations. The June 2024 ransomware attack on Synnovis, an NHS pathology provider, was estimated to cost around £32.7 million, disrupted services across five NHS trusts, and delayed more than 11,000 appointments. The 2025 cyberattack on retailer Marks & Spencer disrupted online operations and was linked to reported losses of up to £300 million.

Figure 1. The Marks & Spencer incident’s reported cost of up to £300 million is roughly nine times the estimated £32.7 million cost of the Synnovis attack, illustrating the scale of impact from incidents that fell outside current NIS reporting obligations. Source: DigitalXRAID, March 2026.

Neither the Synnovis nor the Marks & Spencer incident triggered the reporting obligations the Bill is designed to introduce, despite their combined cost running into hundreds of millions of pounds. That gap is the central justification ministers have given for expanding the regulatory perimeter and tightening reporting timelines.

Risks, Limitations and Caveats

The source material does not specify the exact incident reporting timelines or the financial thresholds for the new two tier penalty regime, since secondary legislation and regulator guidance are expected to define these details after the Bill passes. It is also not yet confirmed how quickly affected organisations, particularly newly captured MSPs and data centre operators, will need to comply once the Bill receives Royal Assent, beyond the general expectation of phased implementation through 2028.

Recommended Actions

Organisations that operate data centres, provide managed IT services, or manage large scale energy demand response should begin reviewing whether they are likely to fall into scope under the expanded NIS perimeter, and should track the Bill’s progress through the House of Lords for confirmation of reporting timelines. Security and compliance teams can use this period to map current incident response and reporting processes against the direction of travel set out in the Bill, particularly around faster reporting of significant incidents, ahead of formal requirements being finalised.

Conclusion

The Cyber Security and Resilience Bill’s passage through report stage and third reading on 10 June 2026 marks a concrete step toward the first major overhaul of UK cyber regulation since 2018. With the Synnovis and Marks & Spencer incidents repeatedly cited as evidence of gaps in the current regime, the direction of the reform, wider scope, new critical supplier powers, and stronger reporting obligations, is clear, even though several operational details remain to be set once the Bill clears the House of Lords.


FAQ

What is the UK Cyber Security and Resilience Bill?

It is legislation that updates the UK’s Network and Information Systems Regulations 2018, expanding which organisations are regulated for cyber security and how incidents must be reported.

What stage has the Bill reached?

The Bill reached report stage and third reading in the House of Commons on 10 June 2026 and now moves to the House of Lords.

Which organisations will be newly covered?

Data centres, large load controllers, and managed service providers are being brought into the NIS regulatory perimeter for the first time.

When will the Bill take effect?

Royal Assent is expected later in 2026, with phased implementation expected to run through to 2028.

Leave a Reply

Your email address will not be published.